CISA Red Team Breaches Two Critical Infrastructure Firms — One Never Noticed
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released findings from two simultaneous red team assessments carried out against critical infrastructure organisations. Using similar attack techniques in both cases, the red team managed to fully compromise each organisation at the domain level, gaining broad access across their networks.
Despite facing comparable methods, the two organisations had strikingly different outcomes when it came to detection. One organisation's security team identified and responded to elements of the intrusion, while the other detected nothing at all throughout the entire exercise. CISA highlighted this gap as a clear illustration of how similar attack tradecraft can produce very different defensive results depending on an organisation's monitoring and response capabilities.
While the report focuses on large critical infrastructure entities, the lesson applies broadly: having security tools in place is not the same as having the visibility and processes needed to catch an active intrusion. Australian small businesses, even those without dedicated security teams, should consider whether they would notice if an attacker gained a foothold in their systems.